CISA - Protection of Information Assets - Section 5.1

Assess identity and access management controls protecting information assets.

Describe identity and access management principles including authentication methods, authorisation models and the role of access controls in limiting user rights to the minimum required. Assess whether implemented controls enforce least privilege, segregation of duties and timely de-provisioning of accounts.

identity and access managementauthenticationauthorizationaccess controls

Practice question for this objective

Free sampleProtection of Information Assetsmedium

Which control type BEST describes a quarterly user access review that compares active accounts in a financial application against current human resources records?

  • APreventive control, because the review stops unauthorised users from obtaining access to the financial application in the first place.
  • BCorrective control, because the review automatically rolls back any incorrect permissions found in the financial application during the review.
  • CCompensating control, because the review substitutes for the absence of a primary segregation of duties control inside the financial application.
  • DDetective control, because the review identifies access that no longer aligns with current employment after it has been granted. Correct
Classify periodic user access reviews as detective controls within the identity and access management lifecycle. Detective controls operate after a transaction or state change to surface deviations from policy; a periodic reconciliation of provisioned accounts against authoritative employment records identifies orphaned or excess access after the fact, which fits the detective control definition rather than preventive, corrective or compensating categories.

Why A is wrong: A preventive control would block inappropriate access before it occurs, but a periodic review takes place after provisioning, so this classification reflects a common confusion about control timing.

Why B is wrong: Corrective controls remediate after detection, and the review itself does not perform the rollback; it produces findings that then drive corrective action, so this confuses detection with the follow-up remediation step.

Why C is wrong: A compensating control substitutes for a missing primary control by management decision, whereas a routine access review is a standalone monitoring activity rather than a substitute, making this a plausible but incorrect classification.

Why D is correct: User access reviews are after-the-fact comparisons that surface dormant, terminated or transferred user accounts that already exist, which is the defining characteristic of a detective control.

See more CISA practice questions, answers explained.

More in this domain

Back to all Protection of Information Assets objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.